UFED and Iphone 5S ...
 
Notifications
Clear all

UFED and Iphone 5S running IOS 8.4

6 Posts
6 Users
0 Reactions
722 Views
(@swefor)
New Member
Joined: 17 years ago
Posts: 3
Topic starter  

Hi, I was examining a mobilephone today and ran in to a huge problem with UFED.
When I tried to do a iTunes backup on the device it just stops and complain about not having a connection to the phone. The funny part is that the AFC-extraction completes without any problems and so does the XRY Logical examination.

I'm trying to run a filedump of the Iphone cause I have to get the mails which is stored on the phone.
So I'm wondering if anyone has got an idea to crack this problem?

I've tried rebooting the computer, phone, change computer, change cables and so on but now I'm stuck and fresh out of ideas.

Thanks for the help in advance!


   
Quote
UnallocatedClusters
(@unallocatedclusters)
Honorable Member
Joined: 13 years ago
Posts: 576
 

Hello,

One trick is to use iTunes itself to make a mobile backup of the iPhone with a known password, such as "password".

Apparently creating a password protected iTunes mobile backup removes encryption that would otherwise be present in a non-password protected mobile backup.

Once you have your password protected mobile backup created by iTunes, you can then use a variety of tools to recover data from the mobile backup itself, such as Lantern/Oxygen etc.


   
ReplyQuote
 lars
(@lars)
Eminent Member
Joined: 17 years ago
Posts: 31
 

Hej Per,

Even if you do get UFED working, it won't get you any email data from an iPhone 5S.

- Lars


   
ReplyQuote
ForensicMeteor
(@forensicmeteor)
Trusted Member
Joined: 11 years ago
Posts: 60
 

You'll need to jailbreak in order to extract email, and even then you'll have a ton of truncated emails. I've written to Cellebrite about this common issue with no solution.


   
ReplyQuote
SamBrown
(@sambrown)
Trusted Member
Joined: 11 years ago
Posts: 97
 

For E-Mails you either have to do a jailbreak or you can print single E-Mails via AirPrint. There is also software available which emulates an AirPrint server and saves each mail as pdf.


   
ReplyQuote
(@gorvq7222)
Reputable Member
Joined: 11 years ago
Posts: 236
 

As to iPhone 5s, I could come up with few solutions

1. See if any laptops or PC/Mac you could seize from suspect's place. The secret plist is in the Lockdown folder because his/her iPhone 5s could have been connectd to laptop/PC/Mac. Once you got the plist, you could get everything from that iPhone 5s.

2. There may be some iTune backups on his/her laptop/PC/Mac, so you could use some tool(ex EPPB) to deal with it.

3. There may be some backups on the iCloud, so so you could use some tool(ex EPPB) to deal with it.

4. Find out the passcode - Based on human nature, the passcode he/her uses is often the info about him/her self. Try those combination first. Second, create an dictionary from his/her laptop/PC/Mac by using EnCase/FTK , this will be the most powerful dictionary attack toward he/her, still based on human nature…


   
ReplyQuote
Share: